Manager, DevSecOps Engineering

The Gap Inc

Pleasanton, CA

JOB DETAILS
SKILLS
Artificial Intelligence (AI), Automation, Bash Scripting, Best Practices, Business Solutions, Cloud Computing, Computer Science, Configuration Management, Continuous Deployment/Delivery, Continuous Improvement, Continuous Integration, Cross-Functional, DevOps, Establish Priorities, Go Programming Language (Golang), Hybrid Cloud, Incident Response, Information/Data Security (InfoSec), Infrastructure Software, Java, Leadership, Machine Learning, Machine Tool, Maintain Compliance, Microservices, Multiplatform/Cross-Platform, Performance Metrics, Process Improvement, Product Engineering, Protective Services, Python Programming/Scripting Language, Regulations, Regulatory Requirements, Requirements Management, Risk Management, Scripting (Scripting Languages), Security Infrastructure, Security Monitoring, Supply Chain, Team Lead/Manager, Test Automation
LOCATION
Pleasanton, CA
POSTED
30+ days ago

About the Role

In this role, you will lead the strategy design and delivery of security engineering solutions that protect the companys assets, infrastructure, and software supply chain. You will manage a team of security and DevOps engineers driving a culture of security-first delivery across Cloud Security, CICD Pipeline Security, Product Security, and Infrastructure Security. You will partner closely with Engineering, Product, and Leadership to set direction and ensure the business ships software with speed and confidence.

What Youll Do

  • Lead the design, development, and implementation of information security solutions across Cloud Security, Infrastructure Security & Product Security.
  • Own the security strategy for CICD pipelines, including automated testing, SAST/DAST scanning, dependency checks, and secrets detection - providing technical advisory and governance across hybrid multi-cloud environments.
  • Drive cloud security posture management, runtime protection, and code security through industry-leading cloud security and edge protection capabilities, ensuring continuous compliance and risk reduction.
  • Define and enforce security policies, standards, and best practices that balance delivery speed with a strong security posture in alignment with regulatory and legal requirements.
  • Lead automation initiatives across cloud security processes, reducing manual effort and improving consistency at scale.
  • Oversee API security standards and runtime protection across services and microservices architectures.
  • Manage infrastructure security controls using infrastructure-as-code and container orchestration tooling in line with container security best practices.
  • Anticipate operational and program risks, developing preventative measures and driving rapid incident response across environments.
  • Translate functional security requirements into technical roadmaps, guiding your team from strategy through to execution.
  • Define, track, and communicate security metrics and key performance indicators - creating actionable insights from data to inform prioritization, demonstrate delivery effectiveness, and drive continuous improvement.
  • Build strong cross-functional relationships with product and engineering squads, embedding security into development workflows and acting as a trusted security advisor at the leadership level.

Who You Are

  • A proven leader with hands-on depth in DevSecOps or security engineering and the ability to inspire, grow, and manage a high-performing team.
  • Demonstrate deep knowledge of infrastructure security practices, concepts, and technologies with proficiency across cloud security capabilities and modern security methodologies.
  • Experience governing CICD pipelines and authoring configuration management and deployment tooling across modern CICD platforms.
  • Strong scripting and development skills across languages such as Python, Bash, Go, or Java.
  • Solid understanding of cloud security concepts, including network segmentation and secrets management across major cloud providers.
  • Experience anticipating operational risks and driving preventative measures across complex, fast-moving engineering environments.
  • A confident communicator who can translate security priorities to developers, stakeholders, and executives alike.
  • Familiarity with AI and machine learning capabilities as applied to DevSecOps and infrastructure management - including AI-assisted threat detection, anomaly detection, intelligent vulnerability triage, and the use of AI-powered tooling to enhance security automation and operational insight - is considered a strong advantage.
  • Background in Computer Science, Information Security, or equivalent practical experience.

About the Company

T

The Gap Inc

Doris and Don Fisher opened the first Gap store in 1969 with a simple idea -- to make it easier to find a pair of jeans and a commitment to do more. Over the last 46 years, the company has grown from a single store to a global fashion business with five brands -- Gap, Banana Republic, Old Navy, Athleta and Intermix. Gap's clothes are available in 90 countries worldwide through 3,300 company-operated stores, almost 400 franchise stores, and e-commerce sites and is still growing. Many companies work to improve their services and businesses every day by using GAP Testers who anonymously go into various places and report back to the companies on everything from cleanliness, customer service to quality control. Being a tester is a very flexible, fun job with lots of benefits.
COMPANY SIZE
10,000 employees or more
INDUSTRY
All
WEBSITE
http://www.gap.com